Storage Device Biometric Authentication and Data Line Deactivation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing semiconductor memory devices, particularly non-volatile memory systems, are limited in their ability to operate independently of host devices that support self-encrypting drive (SED) technology, leading to dependency on specific host device capabilities.
Innovation Solution
A non-volatile memory system that includes a storage device connected to a host device via a physical cable with a power line and a data line, featuring a memory controller with a biometric module for authentication, a biometric processing circuit, a relink trigger circuit, and a data processing circuit capable of encrypting and decrypting data, allowing the system to temporarily deactivate the data line while power is supplied, enabling independent operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If storage devices support SED and operate in dependence on commands from a host device, then security protection is provided, but the storage device cannot operate independently when the host device does not support SED
Solution Approach 1:
The storage device performs relinking operations autonomously without requiring host device commands. The controller detects connection status changes and automatically executes relinking to restore data access, enabling the device to serve itself and operate independently of host device capabilities.
Solution Approach 2:
The storage device proactively performs relinking operations when connection status changes are detected, before the host device can issue commands. This preliminary action ensures data accessibility is restored independently, without waiting for host device support or commands.
2Ease of operation
If the data line is continuously active for data transmission, then data accessibility is maintained, but security vulnerabilities arise when the storage device should be in a secure state
Solution Approach 1:
The data line's operational state is dynamically adjusted based on connection status. The data line is activated during normal data transmission and deactivated when connection changes occur, allowing the system to adapt its security posture dynamically without compromising normal data accessibility.
Solution Approach 2:
The data line is deactivated in advance when connection status changes are detected, preventing potential security vulnerabilities before they can occur. This preliminary protective action ensures that data transmission only occurs when the connection status is confirmed to be normal.
Data Source
Figure 1A
Figure 1B
Figure 1C
AI summary
A storage device is configured to be connected to a host device via a physical cable which includes a power line and a data line. The storage device includes a non-volatile memory, a data path controller configured to temporarily deactivate the data line while power is supplied from the host device via the power line, and a memory controller. The memory controller includes a biometric module configured to receive biometric data and perform user authentication based on the biometric data; a biometric processing circuit configured to change a state of the memory controller, based on a result of the user authentication; and a data processing circuit configured to encrypt and decrypt data. The data path controller is configured to temporarily deactivate the data line in response to the changed state of the memory controller.